7.8
CVE-2007-0257
- EPSS 0.26%
- Published 16.01.2007 23:28:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- CVE-Watchlists
- Open
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities." The developer also cites a past disclosure that was not proven. As of 20070120, the original researcher has released demonstration code
Data is provided by the National Vulnerability Database (NVD)
Grsecurity ≫ Grsecurity Kernel Patch Version1.9.4
Grsecurity ≫ Grsecurity Kernel Patch Version2.0.1
Grsecurity ≫ Grsecurity Kernel Patch Version2.0.2
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.0
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.1
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.2
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.3
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.4
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.5
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.6
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.7
Grsecurity ≫ Grsecurity Kernel Patch Version2.1.8
| Type | Source | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.488 |
| Source | Base Score | Exploit Score | Impact Score | Vector string |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|